File name:

USBVaccine.zip

Full analysis: https://app.any.run/tasks/8b53e140-26cb-46aa-9f32-2c3a4abf921d
Verdict: Suspicious activity
Analysis date: May 29, 2019, 07:33:58
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

C04609BA2C6D39813589479BAF819F62

SHA1:

28624AB7ABB5A71F39453A584C0CC20CB4D655AC

SHA256:

105B6F281483353CB1451A404492381937E16F94505CFBA2257373FC3457D6E6

SSDEEP:

12288:D0W2SLaMucyRTaJMGi8q54cOGitSiUIW+aNF/PDOkf+nvZLkHGPFMygeEUg:12SLaHcyRmn2jOFtVOZ3gJkHGdMCg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • USBVaccineSetup.exe (PID: 2104)
      • USBVaccineSetup.exe (PID: 3252)
      • USBVaccine.exe (PID: 292)
    • Uses Task Scheduler to run other applications

      • USBVaccineSetup.tmp (PID: 3076)
    • Loads the Task Scheduler COM API

      • schtasks.exe (PID: 3268)
      • schtasks.exe (PID: 1380)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • USBVaccineSetup.exe (PID: 2104)
      • WinRAR.exe (PID: 1832)
      • USBVaccineSetup.exe (PID: 3252)
      • USBVaccineSetup.tmp (PID: 3076)
    • Creates files in the program directory

      • USBVaccine.exe (PID: 292)
  • INFO

    • Application was dropped or rewritten from another process

      • USBVaccineSetup.tmp (PID: 3440)
      • USBVaccineSetup.tmp (PID: 3076)
    • Loads dropped or rewritten executable

      • USBVaccineSetup.tmp (PID: 3076)
    • Creates files in the program directory

      • USBVaccineSetup.tmp (PID: 3076)
    • Creates a software uninstall entry

      • USBVaccineSetup.tmp (PID: 3076)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2009:10:23 13:02:17
ZipCRC: 0x908777f8
ZipCompressedSize: 823210
ZipUncompressedSize: 848856
ZipFileName: USBVaccineSetup.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
8
Malicious processes
0
Suspicious processes
5

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start winrar.exe usbvaccinesetup.exe usbvaccinesetup.tmp no specs usbvaccinesetup.exe usbvaccinesetup.tmp schtasks.exe no specs schtasks.exe no specs usbvaccine.exe

Process information

PID
CMD
Path
Indicators
Parent process
292"C:\Program Files\Panda USB Vaccine\USBVaccine.exe" /resident /autovaccinate /experimentalntfs /shownowC:\Program Files\Panda USB Vaccine\USBVaccine.exe
USBVaccineSetup.tmp
User:
admin
Company:
Panda Security
Integrity Level:
HIGH
Description:
USB Vaccine
Exit code:
0
Version:
1.0.1.4
Modules
Images
c:\program files\panda usb vaccine\usbvaccine.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\winspool.drv
1380"schtasks.exe" /create /RU SYSTEM /TN PandaUSBVaccine /XML "C:\Users\admin\AppData\Local\Temp\is-30I4I.tmp\task.xml"C:\Windows\system32\schtasks.exeUSBVaccineSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1832"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\USBVaccine.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2104"C:\Users\admin\AppData\Local\Temp\Rar$EXa1832.26334\USBVaccineSetup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1832.26334\USBVaccineSetup.exe
WinRAR.exe
User:
admin
Company:
Panda Security
Integrity Level:
MEDIUM
Description:
Panda USB Vaccine Setup
Exit code:
0
Version:
1.0.1.4
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1832.26334\usbvaccinesetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3076"C:\Users\admin\AppData\Local\Temp\is-LDPP4.tmp\USBVaccineSetup.tmp" /SL5="$40174,569893,52736,C:\Users\admin\AppData\Local\Temp\Rar$EXa1832.26334\USBVaccineSetup.exe" /SPAWNWND=$30176 /NOTIFYWND=$5014C C:\Users\admin\AppData\Local\Temp\is-LDPP4.tmp\USBVaccineSetup.tmp
USBVaccineSetup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.49.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ldpp4.tmp\usbvaccinesetup.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3252"C:\Users\admin\AppData\Local\Temp\Rar$EXa1832.26334\USBVaccineSetup.exe" /SPAWNWND=$30176 /NOTIFYWND=$5014C C:\Users\admin\AppData\Local\Temp\Rar$EXa1832.26334\USBVaccineSetup.exe
USBVaccineSetup.tmp
User:
admin
Company:
Panda Security
Integrity Level:
HIGH
Description:
Panda USB Vaccine Setup
Exit code:
0
Version:
1.0.1.4
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1832.26334\usbvaccinesetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3268"schtasks.exe" /delete /TN PandaUSBVaccine /FC:\Windows\system32\schtasks.exeUSBVaccineSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
3440"C:\Users\admin\AppData\Local\Temp\is-NJ41G.tmp\USBVaccineSetup.tmp" /SL5="$5014C,569893,52736,C:\Users\admin\AppData\Local\Temp\Rar$EXa1832.26334\USBVaccineSetup.exe" C:\Users\admin\AppData\Local\Temp\is-NJ41G.tmp\USBVaccineSetup.tmpUSBVaccineSetup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.49.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-nj41g.tmp\usbvaccinesetup.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
Total events
1 228
Read events
1 160
Write events
68
Delete events
0

Modification events

(PID) Process:(1832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1832) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\USBVaccine.zip
(PID) Process:(1832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
8
Suspicious files
0
Text files
3
Unknown types
3

Dropped files

PID
Process
Filename
Type
3076USBVaccineSetup.tmpC:\Program Files\Panda USB Vaccine\is-4FHK8.tmp
MD5:
SHA256:
3076USBVaccineSetup.tmpC:\Program Files\Panda USB Vaccine\is-EQV0S.tmp
MD5:
SHA256:
3076USBVaccineSetup.tmpC:\Program Files\Panda USB Vaccine\is-3SPNA.tmp
MD5:
SHA256:
3076USBVaccineSetup.tmpC:\Program Files\Panda USB Vaccine\unins000.exeexecutable
MD5:
SHA256:
292USBVaccine.exeC:\ProgramData\Panda Security\USB Vaccine\Update.inihtml
MD5:
SHA256:
3076USBVaccineSetup.tmpC:\Program Files\Panda USB Vaccine\RunInteractiveWin.exeexecutable
MD5:
SHA256:
3076USBVaccineSetup.tmpC:\Users\admin\AppData\Local\Temp\is-30I4I.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
3076USBVaccineSetup.tmpC:\Users\admin\AppData\Local\Temp\is-30I4I.tmp\task.xmlxml
MD5:
SHA256:
3076USBVaccineSetup.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security\Panda USB Vaccine\Uninstall Panda USB Vaccine.lnklnk
MD5:
SHA256:
3076USBVaccineSetup.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security\Panda USB Vaccine\Panda USB Vaccine on the Web.urltext
MD5:9DABE20BD327B01973AFD09756AC93DE
SHA256:D6236D38C0D44E513222B014B306B008990855BAFE770B7EA10AA0526EB1D1DA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
292
USBVaccine.exe
GET
404
172.217.21.212:80
http://vaccineusbstat.appspot.com/getlastversion?MUID=4c1540f0-625d-4b2e-8aa4-a848b4760137&version=1.0.1.4
US
html
1.51 Kb
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
292
USBVaccine.exe
172.217.21.212:80
vaccineusbstat.appspot.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
vaccineusbstat.appspot.com
  • 172.217.21.212
suspicious

Threats

No threats detected
No debug info